Skip to main content

Create OIDC Client

POST 

/v3/config/extension/oidc/client

Creates an OpenID Connect client. The client enables passwordless login with EUDI Wallet by requesting verifications from individuals. During client creation, a presentation definition specifies which credentials to request - appearing as a QR code or deep link on the authentication page. A presentation definition belongs to at most one client. Give exactly one of identityMatchingAttributes or callbackURI with callbackSecret. The answer holds the generated clientId and clientSecret.

Request​

Body

    presentationDefinitionId stringrequired

    The ID of the presentation definition to use for this client. A presentation definition belongs to at most one client. If the presentation definition has a transaction data template, the template must be login_risk_transaction_non_ts12 or login_risk_transaction. No credential may come with its own transaction data (TS12: payment wallet attestation, software statement, QESAC, SCA credential types): such a definition has another purpose than login.

    name stringrequired

    The name of the client

    redirectURIs string[]

    The redirect URIs for the client. The redirect_uri of an authorisation request must match one of them exactly.

    allowedOrigins string[]

    The web origins of your application.

    identityMatchingAttributes object

    A map of credential identifiers to claim paths used as linking values for identity matching. Each key identifies a credential: the vct of an SD-JWT credential, the doctype of an mdoc credential, or a type value of a W3C credential. The value is the dot-separated path to the claim within that credential. The value of that claim becomes the sub. Give one entry for each credential in the DCQL query of the presentation definition. The key and the path must exist in that DCQL query. Example: {"urn:eudi:pid:1": "email"} uses the email claim of the PID credential for identity matching. Do not send it together with callbackURI.

    property name* string
    callbackURI string

    The URI at which a sub value will be calculated and returned according to the sent presentation. Use an HTTPS endpoint. The endpoint receives the presentations in a POST request and must answer with status 200 and a JSON object that holds sub. Do not send it together with identityMatchingAttributes.

    callbackSecret string

    The secret used to access the callbackURI. Required when callbackURI is set.

    transactionDataAction string

    Possible values: <= 140 characters

    The text that describes the login to the user in the EUDI Wallet, for example Log in to your online bank account. Required when the presentation definition has a transaction data template. Not allowed when the presentation definition has no transaction data. The EUDI Wallet accepts at most 140 characters.

Responses​

Client created

Response Headers
  • Cache-Control string

    Indicates that the response should not be cached.

Schema
    clientId string

    The ID of the created client

    clientSecret string

    The secret of the created client

Loading...